kick it on DotNetKicks.com   Shout it  

Information for every developer: OWASP

A friend of mine recently was the victim of identity theft. Fortunately, for him the bank caught it before any damage was done. But essentially a key logger was installed on his computer which exposed all his personal account information and logins to the attacker.

Today, I was involved in a discussion on a new(er) variant of the well-known SQL Injection attack. In the discussion I was floored that there were some posters who made suggestions which did not properly fix the problem because they continued to use the same vulnerable techniques. They simply moved things around thinking it would fool an attacker.

As developers we can be so lazy sometimes and we continue to shoot ourselves in the foot for it.

Today, I came across OWASP.org (Open Web Application Security Project). Every developer should read the information available on this site - it applies to ALL web development platforms. Check out the free books on the site and start changing how you code right away.

As those who create content for the web, it is our responsibility to protect the web from attackers. By simply changing the way we write applications for the web we can dramatically reduce the attack surface and make the web drastically more safe and secure for all of us.

Please code responsibly.

kick it on DotNetKicks.com   Shout it  

Feedback

# 

Gravatar We welcome you to the world of Web Application Security and OWASP. You should check out your local Chapter meeting and say Hi! 6/9/2008 2:32 PM | noreply@blogger.com (Anonymous)

# 

Gravatar I agree with anonymous! Welcome to the world of OWASP.

Definitely check out your local chapter meetings, always a good place to learn more.

Dave 6/9/2008 2:52 PM | noreply@blogger.com (David Rook)

# 

Gravatar I'd love to join a local chapter. Unfortunately, there isn't one. The closest one is in the next state. I curious what it takes to open a new chapter. 6/10/2008 7:35 AM | noreply@blogger.com (Mark J. Miller)

# 

Gravatar Mark, opening an OWASP Chapter is relatively easy: you just do it! :-)

OWASP only requires you to demonstrate:

- you are sufficiently proficient in application security
- you have a strong leadership to successfully attract attendants to chapter meetings

Andrea 6/13/2008 6:04 AM | noreply@blogger.com (Andrea Cogliati)

Post a comment





 

Please add 1 and 5 and type the answer here:

 

 

Copyright © Mark J. Miller